ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI Leak

ShinyHunters Claims FBI Breach via Unpatched Oracle (TL-2026-2620) is a critical-severity data breach, first published 2026-09-22 and last reviewed 2026-09-27. It is attributed to ShinyHunters with medium confidence, affects Oracle PeopleSoft (PeopleTools), maps to 17 MITRE ATT&CK techniques (T1018, T1036.005, T1071.001), and is covered by 9 detection rules and 24 indicators of compromise.

Key facts for TL-2026-2620

Threat ID
TL-2026-2620
Severity
CRITICAL
Status
ACTIVE
Category
DATA_BREACH
First published
2026-09-22
Last reviewed
2026-09-27
Attribution
ShinyHunters
Attribution confidence
MEDIUM
Motivation
UNKNOWN
Target sectors
government administration, police - law enforcement, human-resources, corporate
Target regions
united states of america
Detection rules
9
Indicators of compromise
24
Updates
2026-09-27

Malware and tooling in ShinyHunters Claims FBI Breach via Unpatched Oracle

Malware and tooling: Clop, scattered lapsus$ hunters

Extortion collective ShinyHunters (Scattered Lapsus$ Hunters) claims it used a new, unpatched Oracle PeopleSoft zero-day to gain remote code execution on the FBI's apply.fbijobs.gov portal, pivot into FBI-managed AWS GovCloud infrastructure, and steal 2-3TB of PII/PHI on FBI employees, agents, and job applicants. The group defaced the portal, released a ~5,000-record sample independently spot-checked as partly accurate by 404 Media, and is demanding the FBI retract a May 2026 FLASH bulletin rather than paying a ransom; the FBI confirms it is investigating but has not confirmed a breach.

How ShinyHunters Claims FBI Breach via Unpatched Oracle works

On the night of Monday, September 21, 2026, the extortion collective ShinyHunters (operating as part of the loosely affiliated "Scattered Lapsus$ Hunters" / "The Com" cluster) told BleepingComputer and 404 Media it had exploited a previously unknown, unpatched remote-code-execution zero-day in Oracle PeopleSoft to compromise the FBI's public-facing Special Agent Applicant Portal (apply.fbijobs.gov). The group claims it used the initial foothold to move laterally into FBI-managed Amazon Web Services GovCloud infrastructure and exfiltrate 2-3TB of data spanning FBI Criminal Justice Information Services records, HR files, the FBI's Medlink medical/employee-health service, and job-applicant records covering current and former employees and prospective Special Agents.

ShinyHunters briefly defaced apply.fbijobs.gov with its trademark Umbreon (Pokemon) logo and a "seized by ShinyHunters" banner before the FBI took the portal offline. As proof, the group gave 404 Media a sample of roughly 5,000 purported employee records containing names, home addresses, phone numbers, and family-member details; 404 Media cross-referenced a subset of the phone numbers against OSINT tooling and found some corresponded to real individuals, including numbers associated with U.S. Department of Justice personnel. Neither the FBI, Oracle, nor AWS has confirmed a breach, a zero-day, or data theft; the FBI's only statement is that it is "aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating." No CVE has been assigned and no proof-of-concept or technical indicators for the underlying PeopleSoft flaw have been published.

Unusually for the group, ShinyHunters states the attack is "not financially motivated" and that it is not seeking a ransom but rather "coercion": it is demanding the FBI, addressed to Director Kash Patel and Cyber Division Assistant Director Brett Leatherman, retract or correct a May 15, 2026 FBI FLASH/PSA bulletin that named ShinyHunters and Scattered Spider (tracked by Google as UNC6040/UNC6395) for a Salesforce data-theft extortion campaign and accused the group of harassment tactics including swatting and threats against victims' families. ShinyHunters also claims it is now exploiting the same new PeopleSoft zero-day against other, unnamed Fortune 500 organizations.

The incident sits inside an active feud between ShinyHunters and the Cl0p ransomware gang over ownership of a separate, already-patched Oracle flaw: CVE-2025-61882, an unauthenticated RCE in the BI Publisher Integration of Oracle E-Business Suite's Concurrent Processing component that Cl0p exploited as a zero-day from August 2025 before an October 2025 patch. Scattered Lapsus$ Hunters (including ShinyHunters) subsequently leaked the exploit and partial Oracle source code, asserting Cl0p had obtained "their" exploit without authorization. Days before the FBI claims, on September 19, 2026, ShinyHunters hijacked Cl0p's own dark-web leak site via an unauthenticated file-upload vulnerability in its Grav CMS, demanding an eight-figure cut of Cl0p's EBS extortion proceeds. ShinyHunters says it exfiltrated the leak site's source code, Grav CMS plugins, and server logs, and -- most significantly -- the private keys for Cl0p's Tor (.onion) hidden service, which it claims would let it operate Cl0p's dark-web leak address independently. ShinyHunters is also the actor Google Threat Intelligence Group/Mandiant track as UNC6240, which exploited a different, since-patched Oracle PeopleSoft PeopleTools RCE (CVE-2026-35273, patched out-of-band by Oracle on June 10, 2026) as a zero-day against more than 100 organizations, predominantly in education, in mid-2026 -- establishing a clear pattern of the group weaponizing unauthenticated Oracle enterprise-application RCEs as zero-days ahead of vendor disclosure. The zero-day claimed in this FBI incident is presented by ShinyHunters as a newly found, still-unpatched flaw distinct from CVE-2026-35273.

The CVE-2026-35273 campaign gives the clearest public technical picture of how UNC6240/ShinyHunters operates once inside a PeopleSoft environment, and is the closest available proxy for the mechanics of the still-undisclosed FBI zero-day. Per Rapid7 and Arctic Wolf incident-response telemetry, the actor exploited an unauthenticated SSRF-to-RCE chain via the /PSEMHUB/hub and /PSIGW/HttpListeningConnector Integration Gateway endpoints, using the SSRF to force outbound SMB connections capable of capturing Windows NetNTLM hashes; deployed MeshCentral remote-access agents disguised as Microsoft Azure binaries (e.g. meshagent64-azure-ops.exe) that beaconed to a C2 domain, azurenetfiles.net, masquerading as Azure over WSS/443; dropped .jsp web shells and XMLDecoder-based persistence under compromised PeopleSoft webserv/PSEMHUB.war paths; extracted credentials directly from PeopleSoft's psappsrv.cfg application-server configuration files; ran credential-spraying scripts and remote-system discovery to map web/app/batch server tiers for lateral movement; staged stolen data with zstd compression prior to exfiltration; and left a README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT marker on compromised hosts before publishing victim data to its leak site. This same actor's demonstrated, PeopleSoft-specific tradecraft is the basis for the additional ATT&CK techniques mapped below, since no independent technical telemetry has yet been published for the FBI-specific zero-day itself.

The claimed FBI compromise is also the latest in a string of 2026 FBI-adjacent incidents: in March 2026 the FBI disclosed a separate, unrelated "major incident" breach of its Digital Collection System Network (DCSNet) wiretap/surveillance infrastructure -- suspected to be Chinese state-sponsored and reportedly reached via a compromised ISP vendor -- and the Iran-linked "Handala" group separately compromised FBI Director Kash Patel's personal Gmail account and published stolen emails and photos. Those incidents are unrelated to ShinyHunters and are noted here only as target-profile context.

MITRE ATT&CK techniques used in TL-2026-2620

Discovery

T1018 Remote System Discovery

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location

Command and Control

T1071.001 Web Protocols; T1219 Remote Access Tools

Credential Access

T1110.003 Password Spraying; T1187 Forced Authentication; T1552.001 Credentials In Files; T1552.004 Private Keys

Initial Access

T1190 Exploit Public-Facing Application

Collection

T1213 Data from Information Repositories; T1530 Data from Cloud Storage; T1560 Archive Collected Data

Impact

T1491.002 External Defacement

Persistence

T1505.003 Web Shell

Resource Development

T1588.005 Exploits; T1588.006 Vulnerabilities

Reconnaissance

T1595.002 Vulnerability Scanning

Affected products and versions in ShinyHunters Claims FBI Breach via Unpatched Oracle

  • Oracle — PeopleSoft (PeopleTools)
    Vulnerable versions: unspecified -- claimed zero-day, no vendor advisory or CVE published as of 2026-09-22
    Fixed in: none published as of 2026-09-22
  • Federal Bureau of Investigation — FBIjobs.gov / apply.fbijobs.gov (Special Agent Applicant Portal)
    Vulnerable versions: hosted service, no version applicable
    Fixed in: taken offline by the FBI pending investigation
  • Amazon Web Services — AWS GovCloud (US) -- FBI-managed tenant
    Vulnerable versions: hosted infrastructure, no version applicable

Remediation for ShinyHunters Claims FBI Breach via Unpatched Oracle

Patches

  • No vendor patch or advisory exists yet for the specific zero-day claimed in this incident; monitor oracle.com/security-alerts for a new PeopleSoft/PeopleTools bulletin
  • Apply Oracle's June 10, 2026 out-of-band Security Alert for CVE-2026-35273 (PeopleTools 8.61/8.62) if not already deployed
  • Confirm the October 2025 Oracle patch for CVE-2025-61882 (E-Business Suite Concurrent Processing / BI Publisher Integration) is applied on any EBS instances

Immediate actions

  • Audit and restrict internet-facing Oracle PeopleSoft / PeopleTools deployments; consider temporarily gating access behind a WAF or VPN pending vendor guidance on the newly claimed zero-day
  • Rotate credentials and review access logs for HR, Medlink-equivalent health/benefits, and Criminal-Justice-Information-Services-adjacent integrations reachable from PeopleSoft application servers
  • Review cloud (AWS GovCloud or equivalent) IAM, VPC flow, and CloudTrail logs for anomalous lateral movement originating from PeopleSoft/PeopleTools application hosts
  • Enable defacement/file-integrity monitoring on public-facing recruitment and HR portals

Workarounds

  • Restrict network reachability of PeopleSoft/PeopleTools administrative and integration HTTP endpoints to known-good IP ranges
  • Increase logging verbosity and alerting on Oracle PeopleSoft HTTP request anomalies while a patch for the new flaw is unavailable
  • Take non-essential public-facing PeopleSoft-hosted portals offline or place behind additional authentication pending vendor guidance

Longer-term hardening

  • Confirm the June 10, 2026 Oracle out-of-band patch for CVE-2026-35273 is applied on all PeopleTools 8.61/8.62 instances as a baseline, since this actor has now targeted PeopleSoft twice in 2026
  • Network-segment PeopleSoft/EBS application tiers from cloud management planes and identity providers to blunt RCE-to-cloud pivoting
  • Establish an expedited patch/mitigation SLA for Oracle enterprise-application advisories given repeated zero-day use against EBS (CVE-2025-61882) and PeopleSoft (CVE-2026-35273) by this actor cluster in 2025-2026
  • Extend Salesforce/SaaS OAuth-token and vishing defenses already built for the UNC6040/UNC6395 (ShinyHunters/Scattered Spider) FLASH advisory to cover Oracle on-prem/enterprise application exposure

Timeline of ShinyHunters Claims FBI Breach via Unpatched Oracle

  • Threat actors, later attributed to Cl0p, begin exploiting CVE-2025-61882 as a zero-day against Oracle E-Business Suite Concurrent Processing / BI Publisher Integration, weeks ahead of a patch.
  • Scattered Lapsus$ Hunters (including ShinyHunters) leak the CVE-2025-61882 exploit archive and partial Oracle source code, publicly asserting Cl0p obtained the exploit from them without authorization -- the origin of the ongoing ShinyHunters/Cl0p feud.
  • FBI analysts detect abnormal log activity later attributed to a separate, unrelated 'major incident' breach of the FBI's Digital Collection System Network (DCSNet) wiretap/surveillance infrastructure via a compromised ISP vendor.
  • Iran-linked group Handala publishes personal emails and photos it says were exfiltrated from FBI Director Kash Patel's personal Gmail account, an incident unrelated to ShinyHunters.
  • The FBI publishes a FLASH/PSA bulletin naming ShinyHunters and Scattered Spider (tracked by Google as UNC6040/UNC6395) for a Salesforce data-theft extortion campaign and describing harassment tactics including swatting -- the bulletin ShinyHunters later demands be retracted.
  • Oracle issues an out-of-band Security Alert patching CVE-2026-35273, a critical (CVSS 9.8) unauthenticated RCE in PeopleSoft PeopleTools 8.61/8.62; Google Threat Intelligence Group/Mandiant confirm ShinyHunters (UNC6240) had exploited it as a zero-day against 100+ organizations, mostly in education.
  • ShinyHunters exploits an unauthenticated file-upload flaw in the Grav CMS powering Cl0p's dark-web leak site, seizes it, and demands an eight-figure share of Cl0p's Oracle EBS extortion proceeds.
  • ShinyHunters claims it exploited a new, unpatched Oracle PeopleSoft zero-day for RCE against the FBI's apply.fbijobs.gov Special Agent Applicant Portal on Monday night, then moved laterally into FBI-managed AWS GovCloud infrastructure and exfiltrated an alleged 2-3TB of data.
  • ShinyHunters publicly demands the FBI, addressed to Director Kash Patel and Cyber Division Assistant Director Brett Leatherman, retract the May 15 FLASH report within one week, and claims it is now exploiting the same new PeopleSoft zero-day against other organizations including Fortune 500 companies.
  • ShinyHunters defaces apply.fbijobs.gov with its Umbreon logo and a 'seized by ShinyHunters' message; 404 Media publishes a report including a verified-partly-accurate ~5,000-record employee sample; the FBI states it is investigating claims affecting FBIjobs.gov.

Update history for TL-2026-2620

  • 2026-09-27 — tweetfeed.live community intel: New TL_OSINT_Scan community intel: 1 newly-corroborated indicator(s), 3 community-related indicator(s).

Sources cited for ShinyHunters Claims FBI Breach via Unpatched Oracle

More in data breach

Detection coverage for TL-2026-2620

As of 2026-09-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2620 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-2620

3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats